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DETAILED ACTION 

1 . Claims 1 -3 1 have been examined. 

Claim Rejections - 35 USC § 102 

2. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the 
basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(e) the invention was described in (1) an application for patent, published under section 122(b), by another filed 
in the United States before the invention by the applicant for patent or (2) a patent granted on an application for 
patent by another filed in the United States before the invention by the applicant for patent, except that an 
international application filed under the treaty defined in section 351(a) shall have the effects for purposes of this 
subsection of an application filed in the United States only if the international application designated the United 
States and was published under Article 21(2) of such treaty in the English language. 

3. Claims 1, 10 and 19 are rejected under 35 U.S.C. 102(e) as being anticipated by US 
Publication No. 2005/002 1 78 1 to Sunder et al. 

Referring to claim 1, Sunder et al. disclose receive an authentication request from a 
cardholder system (i.e. client device)(see paragraphs [0005] & [0007]), forward the 
authentication request to an access control server (see paragraph [0008]), relay authentication 
information between the access control server and the cardholder system receive an 
authentication response from the access control server and forward the authentication response to 
the cardholder system (see paragraphs [[0010] &[001 1]). 

Claims 10 and 19 are rejected on the same rationale as claim 1 above. 

Claim Rejections - 35 USC § 103 

4. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 
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(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in 
section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are 
such that the subject matter as a whole would have been obvious at the time the invention was made to a person 
having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the 
manner in which the invention was made. 

5. Claims 2, 3,9, 1 1, 12, 18, 20 and 21 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Sunder et al. as applied to claims 1 and 10 above, and further in view of US 
Publication No. 2003/0046541 to Gerdes et al. 

Referring to claim 2, Sunder et al. disclose an electronic commerce card authentication 
system (see claim 1 above). Sunder et al. do not expressly disclose the authentication response is 
adapted to be analyzed by a merchant system. Gerdes et al. disclose the authentication response 
is adapted to be analyzed by a merchant system (see paragraph [0014] - the authentication server 
sends a confirmation of the user identity to the service provider. Based on the confirmation, the 
service provider finally grants service access to the user). At the time the invention was made, it 
would have been obvious to a person of ordinary skill in the art to modify the system disclose by 
Sunder et al. to allow the merchant system to analyze the authentication response. One of 
ordinary skill in the art would have been motivated to do this because it provides authentication 
of a user to a service provider (see paragraph [0010] of Gerdes et al.). 

Referring to claim 3, Sunder et al. disclose an electronic commerce card authentication 
system (see claim 1 above). Sunder et al. do not expressly disclose wherein the central 
transaction server is adapted to forward a copy of the authentication response to an 
authentication history server to be archived. Gerdes et al. disclose the central transaction server 
is adapted to forward a copy of the authentication response to an authentication history server to 
be archived (see paragraph [0057]). At the time the invention was made, it would have been 
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obvious to a person of ordinary skill in the art to modify the system disclose by Sunder et al. to 
include a copy of the authentication response to an authentication history server. One of 
ordinary skill in the art would have been motivated to do this because it provides a history of 
authentication transaction (see paragraph [0057 of Gerdes et al). 

Referring to claim 9, Sunder et al. disclose the electronic commerce card authentication 
system (see claim 1 above). Sunder et al. do not expressly disclose the central transaction server 
is adapted to initiate a charge request via a card association network in response to receiving an 
authentication response from the access control server. Gerdes et al. disclose the central 
transaction server is adapted to initiate a charge request via a card association network in 
response to receiving an authentication response from the access control server (see paragraph 
[0014]). At the time the invention was made, it would have been obvious to a person of ordinary 
skill in the art to modify the system disclose by Sunder et al. to include the central transaction 
server is adapted to initiate a charge request via a card association network in response to 
receiving an authentication response from the access control server. One of ordinary skill in the 
art would have been motivated to do this because it provides an additional level of security. 

Claims 1 1 and 20 are rejected on the same rationale as claim 2 above. 

Claims 12 and 21 are rejected on the same rationale as claim 3 above. 

Claims 18 and 27 are rejected on the same rationale as claim 9 above. 
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6. Claims 4-6, 13-15, 22-24, and 28 -31 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Sunder et al. as applied to claims 1,10 and 14 above, and further in view of 
US Publication No. 2004/0254848 to Golan et al. 

Referring to claims 4 and 5, Sunder et al. disclose the electronic commerce card 
authentication system (see claim 1 above). Sunder et al. do not expressly disclose wherein the 
central transaction server is further adapted receive a verifying enrollment request from a 
directory server, and to send a verifying enrollment response to the directory server; wherein the 
central transaction server is adapted to send the verifying enrollment response in response to a 
query to the access control server. Golan et al. disclose wherein the central transaction server is 
further adapted receive a verifying enrollment request from a directory server, and to send a 
verifying enrollment response to the directory server; wherein the central transaction server is 
adapted to send the verifying enrollment response in response to a query to the access control 
server (see paragraphs [0094]-[0097] & claims 5,6). At the time the invention was made, it 
would have been obvious to a person of ordinary skill in the art to modify the system disclose by 
Sunder et al. to include the system wherein the central transaction server is further adapted 
receive a verifying enrollment request from a directory server, and to send a verifying enrollment 
response to the directory server; wherein the central transaction server is adapted to send the 
verifying enrollment response in response to a query to the access control server. One of 
ordinary skill in the art would have been motivated to do this because provides an additional 
level of verification, thereby securing the system. 

Referring to claim 6, Sunder et al. disclose the electronic commerce card authentication 
system (see claim 1 above). Sunder et al. do not expressly disclose the central transaction server 
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is adapted to send the verifying enrollment response to the directory server with or without 
querying the access control server, and is further adapted to query the access control server in 
response to receiving an authentication request. Golan et al. disclose the central transaction 
server is adapted to send the verifying enrollment response to the directory server with or 
without querying the access control server, and is further adapted to query the access control 
server in response to receiving an authentication request (see paragraphs [0099] &[0100]). At 
the time the invention was made, it would have been obvious to a person of ordinary skill in the 
art to modify the system disclose by Sunder et al. to include the system wherein the central 
transaction server is adapted to send the verifying enrollment response to the directory server 
with or without querying the access control server, and is further adapted to query the access 
control server in response to receiving an authentication request. One of ordinary skill in the art 
would have been motivated to do this because provides an additional level of verification, 
thereby securing the system. 

Claims 13, 22, 28, and 30 are rejected on the same rationale as claim 4 above. 

Claims 14 and 23 are rejected on the same rationale as claim 5 above. 

Claims 15 and 24 are rejected on the same rationale as claims 6 above. 

Referring to claims 29 and 31, Sunder et al. disclose the electronic commerce card 
authentication system (see claims 28 and 30 respectively above). Sunder et al. do not expressly 
disclose modifying the verifying enrollment request from a directory server, and forwarding the 
modified verifying enrollment response to the directory server. Golan et al. disclose receiving a 
verifying enrollment request from a directory server, and to send a verifying enrollment response 
to the directory server and sending the verifying enrollment response in response to a query to 
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the access control server (see paragraphs [0094]-[0097] & claims 5,6). Golan et al. do not teach 
the request being modified; however, the concept of modifying data is well known in the art of 
data processing. Thus, at the time the invention was made, it would have been obvious to a 
person of ordinary skill in the art to modify the system disclose by Sunder et al. to include the 
steps of disclose receiving a verifying enrollment request from a directory server, and to send a 
verifying enrollment response to the directory server and sending the verifying enrollment 
response in response to a query to the access control server. One of ordinary skill in the art 
would have been motivated to do this because provides an additional level of verification, 
thereby securing the system. 

7. Claims 7, 16 and 25 are rejected under 35 U.S.C. 103(a) as being unpatentable over 
Sunder et al. as applied to claims 1,10 and 19 above, and further in view of US Publication No. 
2001/0029496 to Otto et al. 

Referring to claim 7, Sunder et al. disclose the electronic commerce card authentication 
system (see claim 1 above). Sunder et al. do not expressly disclose the authentication request 
includes a pseudonym corresponding to an electronic commerce card account number and 
previously created by the central transaction server (see paragraph [0027] - [0029] -the user can 
submit the anonymous identifying information to the merchant; the merchant submits the request 
the banking network who then forwards the request to the financial institution that issued the 
anonymous card). At the time the invention was made, it would have been obvious to a person 
of ordinary skill in the art to modify the system disclose by Sunder to include a pseudonym 
corresponding the an electronic commerce card account number in the authentication request, the 
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pseudonym previously created by the central transaction server. One of ordinary skill in the art 
would have been motivated to do this because it secures user's identity by providing a means for 
users to anonymously purchase goods and services over a network (see Otto et al. paragraph 
[0007]). 

Claims 16 and 25 are rejected on the same rationale as claim 7 above. 

8. Claims 8, 17 and 26 are rejected under 35 U.S.C 103(a) as being unpatentable over 
Sunder et al. as applied to claims 1,10 and 19 above, and further in view of US Publication No. 
2002/01 16341 to Hogan et al. 

Referring to claim 8, Sunder et al. disclose the electronic commerce card authentication 
system (see claim 1 above). Sunder et al. do not expressly disclose the authentication request 
includes a pseudonym previously created by a merchant system that corresponds to an electronic 
commerce card account number. Hogan et al. disclose the authentication request includes a 
pseudonym previously created by a merchant system that corresponds to an electronic commerce 
card account number (see paragraph [0025]). At the time the invention was made, it would have 
been obvious to a person of ordinary skill in the art to modify the system disclose by Sunder et 
al. to include a pseudonym previously created by the central transaction server. One of ordinary 
skill in the art would have been motivated to do this because it protects messages and 
information being transmitted during a transaction (see Hogan et al. paragraph [0016]).. 

Claims 17 and 26 are rejected on the same rationale as claim 8 above. 
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Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Jalatee Worjloh whose telephone number is (571) 272-6714. The 
examiner can normally be reached on Mondays-Thursdays 8:30 - 7:00. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, James Trammell can be reached on (571) 272-6712. The fax phone number for the 
organization where this application or proceeding is assigned is 571-273-8300 for Regular/ After 
Final Actions and 571-273-6714 for Non-Official/Draft. 

Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR 
system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would 
like assistance from a USPTO Customer Service Representative or access to the automated 
information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 
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Patent Examiner 
Art Unit 3621 
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